| » Virus checking on any incoming electronic
mail and attachments. |
| » Backup and recovery disciplines for data,
including storage of copies off premises. |
| » Incident management process covering
recording, investigating, remedying and
preventing reoccurrence. |
| » Identify risk/threats and evaluate
consequences in terms of impact on business. |
| » Prepare a company Information Security
policy. |
| » Staff agreement defining everyone's
responsibilities for protecting privacy of
company, employee and customer information, acknowledging the company's
right to monitor the use of company facilities and
committing to reporting any form of incident. |
| » Access control to identify every user and
define their access rights, including process to
refresh any method allowing impersonation such as passwords. |
| » Business survival planning for action in
case of loss of premises or key equipment. |
| » Access controls for premises, including
reception, door access, B&E bars, intrusion
detection, property marking and devices for securing laptops. |
| » Thorough testing of any logic used in IT
& IS systems before live use, including Intranet
and Internet based services. |
| » Inclusion of security obligations in any
contract with third parties with access to
information, not forgetting cleaners, plant suppliers, meter readers
and any other invisible suppliers with physical access to premises. |
| » Independent review of security system
controls and their operation. |